First published: Sat Aug 21 1999(Updated: )
The scriptlet.typelib ActiveX control is marked as "safe for scripting" for Internet Explorer, which allows a remote attacker to execute arbitrary commands as demonstrated by Bubbleboy.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Internet Explorer | =4.0 | |
Internet Explorer | =5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-0668 has a high severity rating due to its ability to allow remote attackers to execute arbitrary commands.
To fix CVE-1999-0668, update to a later version of Internet Explorer that does not include the vulnerable ActiveX control.
CVE-1999-0668 affects Internet Explorer versions 4.0 and 5.0.
The impact of CVE-1999-0668 allows attackers to execute unwanted commands on a user's system remotely.
A temporary workaround for CVE-1999-0668 includes disabling ActiveX controls within Internet Explorer settings.